General Industrial Controls Lynx+ Gateway Cleartext Transmission Vulnerability

Vulnerability

A cleartext transmission vulnerability has been identified in General Industrial Controls Lynx+ Gateway, specifically in versions R08, V03, V05, and V18. This vulnerability allows an attacker to intercept network traffic and access sensitive information, including plaintext credentials. The issue arises from weak password requirements and missing authentication for critical functions, which could lead to unauthorized access and manipulation of the device.

Impact

Exploitation of this vulnerability could result in the interception of sensitive information, including passwords, creating an opportunity for unauthorized access to the affected system.

Remediation

General Industrial Controls has not responded to coordination efforts. Users are encouraged to contact GIC for more information. CISA recommends minimizing network exposure for control system devices, isolating them from business networks, and using secure remote access methods, such as VPNs.

Added: Nov 15, 2025, 12:21 AM
Updated: Nov 15, 2025, 12:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
1.1
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.